Topology (HackTheBox): LaTeX Injection → Local File Read
7 words
1 minute
Topology (HackTheBox): LaTeX Injection → Local File Read
Share Article
If this article helped you, please share it with others!
Topology (HackTheBox): LaTeX Injection → Local File Read
https://achux21.github.io/posts/topology/ Spooky Query Leaks (USC-CTF 2024): SQLite3 SQL Injection via UPSERT
JWT - Unsecure File Signature (Root-Me): JWT Algorithm Confusion Attack
Related Posts Smart
1
1337 Local CTF: Notebook — Smarty SSTI → WAF Bypass → File Read
CTF Exploiting Smarty template injection and bypassing a substring WAF with string concatenation.
2
1337 Local CTF: new intra — IDOR → Staff Login → Admin Page
CTF Chaining a profile-update IDOR into staff authentication and retrieving the flag from the admin page.
3
TwoMillion (HackTheBox): API Manipulation → Command Injection → Kernel Exploit
Box Manipulating the HackTheBox API endpoints to escalate privileges, exploiting a command injection in the admin panel, and using an old kernel exploit for root.
4
C.O.P (HackTheBox): SQL Injection → Pickle Deserialization RCE
Web Exploitation Exploiting a SQL injection vulnerability to inject a malicious Pickle payload, achieving remote code execution and capturing the flag.
5
Pilgrimage (HackTheBox): Git Exposure → ImageMagick CVE-2022-44268 → PrivEsc
Box Discovering an exposed .git repository, exploiting ImageMagick arbitrary file read (CVE-2022-44268) to steal credentials, and escalating privileges via a vulnerable system binary.
Random Posts Random